* [OE-core][scarthgap 01/11] nghttp2: set status for CVE-2026-58055
2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 02/11] binutils: fix CVE-2025-1147 Yoann Congal
` (9 subsequent siblings)
10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
CVE-2026-58055 affects the nghttpx proxy when forwarding HTTP/1.1
Upgrade requests with a Content-Length header and body.
The default recipe does not build nghttpx. Add a conditional
CVE_STATUS entry so the CVE remains unpatched if app support is
enabled, while default builds are marked not-applicable-config.
References:
https://nvd.nist.gov/vuln/detail/CVE-2026-58055
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
meta/recipes-support/nghttp2/nghttp2_1.61.0.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta/recipes-support/nghttp2/nghttp2_1.61.0.bb b/meta/recipes-support/nghttp2/nghttp2_1.61.0.bb
index ebba15db282..9ed27b72770 100644
--- a/meta/recipes-support/nghttp2/nghttp2_1.61.0.bb
+++ b/meta/recipes-support/nghttp2/nghttp2_1.61.0.bb
@@ -16,6 +16,8 @@ PACKAGECONFIG[manpages] = ""
# first place
EXTRA_OECMAKE = "-DENABLE_EXAMPLES=OFF -DENABLE_APP=OFF -DENABLE_HPACK_TOOLS=OFF -DENABLE_PYTHON_BINDINGS=OFF"
+CVE_STATUS[CVE-2026-58055] = "${@bb.utils.contains('EXTRA_OECMAKE', '-DENABLE_APP=OFF', 'not-applicable-config: nghttpx proxy is not built in the default nghttp2 configuration', 'unpatched', d)}"
+
PACKAGES =+ "lib${BPN} ${PN}-proxy "
RDEPENDS:${PN} = "${PN}-proxy (>= ${PV})"
^ permalink raw reply related [flat|nested] 25+ messages in thread* [OE-core][scarthgap 02/11] binutils: fix CVE-2025-1147
2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 01/11] nghttp2: set status for CVE-2026-58055 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 03/11] binutils: fix CVE-2025-8224 Yoann Congal
` (8 subsequent siblings)
10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-1147
https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=7be4186c22f89a87fff048c28910f5d26a0f61ce
Test results:
binutils-cross-testsuite 2.42 (x86_64-oe-linux):
Before:
binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported
gas: 1871 passed, 4 unexpected failures, 2 unsupported
ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported
After:
binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported (+2 new passes from nm --ifunc-chars=-- tests)
gas: 1871 passed, 4 unexpected failures, 2 unsupported
ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported
Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=7be4186c22f89a87fff048c28910f5d26a0f61ce]
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
.../binutils/binutils-2.42.inc | 1 +
.../binutils/binutils/CVE-2025-1147.patch | 110 ++++++++++++++++++
2 files changed, 111 insertions(+)
create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch
diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc
index d455acd7863..063c6cc2a43 100644
--- a/meta/recipes-devtools/binutils/binutils-2.42.inc
+++ b/meta/recipes-devtools/binutils/binutils-2.42.inc
@@ -78,5 +78,6 @@ SRC_URI = "\
file://CVE-2025-69652.patch \
file://CVE-2026-6846.patch \
file://CVE-2025-69645.patch \
+ file://CVE-2025-1147.patch \
"
S = "${WORKDIR}/git"
diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch b/meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch
new file mode 100644
index 00000000000..9a95775d3f0
--- /dev/null
+++ b/meta/recipes-devtools/binutils/binutils/CVE-2025-1147.patch
@@ -0,0 +1,110 @@
+From 7be4186c22f89a87fff048c28910f5d26a0f61ce Mon Sep 17 00:00:00 2001
+From: Dmitry Klochkov <dmitry.klochkov@bell-sw.com>
+Date: Tue, 9 Sep 2025 12:06:25 +0200
+Subject: [PATCH] nm: fix treating an ifunc symbol as a stab if
+ '--ifunc-chars=--' is given
+
+If an ifunc symbol is processed in print_symbol(), a 'type' field of a
+'syminfo' structure is set to any character specified by a user with an
+'--ifunc-chars' option. But afterwards the 'type' field is used to
+check whether a symbol is a stab in print_symbol_info_{bsd,sysv}()
+functions in order to print additional stab related data. If the 'type'
+field equals '-', a symbol is treated as a stab. If '--ifunc-chars=--'
+is given, all ifunc symbols will be treated as stab symbols and
+uninitialized stab related fields of the 'syminfo' structure will be
+printed which can lead to segmentation fault.
+
+To fix this, check if a symbol is a stab before override the 'type'
+field. Also, add a test case for this fix.
+
+ PR binutils/32556
+ * nm.c (extended_symbol_info): Add is_stab.
+ (print_symbol): Check if a symbol is a stab.
+ (print_symbol_info_bsd): Use info->is_stab.
+ (print_symbol_info_sysv): Use info->is_stab.
+ * testsuite/binutils-all/nm.exp: Test nm --ifunc-chars=--.
+
+Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=32556
+Fixes: e6f6aa8d184 ("Add option to nm to change the characters displayed for ifunc symbols")
+Signed-off-by: Dmitry Klochkov <dmitry.klochkov@bell-sw.com>
+
+CVE: CVE-2025-1147
+Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=7be4186c22f89a87fff048c28910f5d26a0f61ce]
+
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ binutils/nm.c | 10 +++++++---
+ binutils/testsuite/binutils-all/nm.exp | 17 +++++++++++++++++
+ 2 files changed, 24 insertions(+), 3 deletions(-)
+
+diff --git a/binutils/nm.c b/binutils/nm.c
+index dce9207f44f..c3d118a93c3 100644
+--- a/binutils/nm.c
++++ b/binutils/nm.c
+@@ -70,6 +70,7 @@ struct extended_symbol_info
+ bfd_vma ssize;
+ elf_symbol_type *elfinfo;
+ coff_symbol_type *coffinfo;
++ bool is_stab;
+ /* FIXME: We should add more fields for Type, Line, Section. */
+ };
+ #define SYM_VALUE(sym) (sym->sinfo->value)
+@@ -1208,8 +1209,11 @@ print_symbol (bfd * abfd,
+
+ bfd_get_symbol_info (abfd, sym, &syminfo);
+
++ info.is_stab = false;
++ if (syminfo.type == '-')
++ info.is_stab = true;
+ /* PR 22967 - Distinguish between local and global ifunc symbols. */
+- if (syminfo.type == 'i'
++ else if (syminfo.type == 'i'
+ && sym->flags & BSF_GNU_INDIRECT_FUNCTION)
+ {
+ if (ifunc_type_chars == NULL || ifunc_type_chars[0] == 0)
+@@ -1873,7 +1877,7 @@ print_symbol_info_bsd (struct extended_symbol_info *info, bfd *abfd)
+
+ printf (" %c", SYM_TYPE (info));
+
+- if (SYM_TYPE (info) == '-')
++ if (info->is_stab)
+ {
+ /* A stab. */
+ printf (" ");
+@@ -1902,7 +1906,7 @@ print_symbol_info_sysv (struct extended_symbol_info *info, bfd *abfd)
+
+ printf ("| %c |", SYM_TYPE (info));
+
+- if (SYM_TYPE (info) == '-')
++ if (info->is_stab)
+ {
+ /* A stab. */
+ printf ("%18s| ", SYM_STAB_NAME (info)); /* (C) Type. */
+diff --git a/binutils/testsuite/binutils-all/nm.exp b/binutils/testsuite/binutils-all/nm.exp
+index fea68bf76bc..1feb8578fba 100644
+--- a/binutils/testsuite/binutils-all/nm.exp
++++ b/binutils/testsuite/binutils-all/nm.exp
+@@ -329,6 +329,23 @@ if [is_elf_format] {
+ fail "$testname (local ifunc)"
+ }
+
++ # PR 32556
++ # Test nm --ifunc-chars=--
++
++ set got [binutils_run $NM "$NMFLAGS --ifunc-chars=-- $tmpfile"]
++
++ if [regexp -line "^\\S+ - global_foo$" $got] then {
++ pass "$testname=-- (global ifunc)"
++ } else {
++ fail "$testname=-- (global ifunc)"
++ }
++
++ if [regexp -line "^\\S+ - local_foo$" $got] then {
++ pass "$testname=-- (local ifunc)"
++ } else {
++ fail "$testname=-- (local ifunc)"
++ }
++
+ if { $verbose < 1 } {
+ remote_file host delete "tmpdir/ifunc.o"
+ }
^ permalink raw reply related [flat|nested] 25+ messages in thread* [OE-core][scarthgap 03/11] binutils: fix CVE-2025-8224
2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 01/11] nghttp2: set status for CVE-2026-58055 Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 02/11] binutils: fix CVE-2025-1147 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 04/11] binutils: fix CVE-2026-15003 Yoann Congal
` (7 subsequent siblings)
10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2025-8224
https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=db856d41004301b3a56438efd957ef5cabb91530
[Adapted for binutils 2.42: only the shstrtabsize overflow check in
bfd_elf_get_str_section applies. The second upstream hunk (DT_STRTAB)
does not apply as 2.42 already unconditionally null-terminates the
dynamic string table.]
Test results:
binutils-cross-testsuite 2.42 (x86_64-oe-linux):
Before:
binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported
gas: 1871 passed, 4 unexpected failures, 2 unsupported
ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported
After:
binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported
gas: 1871 passed, 4 unexpected failures, 2 unsupported
ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported
Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=db856d41004301b3a56438efd957ef5cabb91530]
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
.../binutils/binutils-2.42.inc | 1 +
.../binutils/binutils/CVE-2025-8224.patch | 54 +++++++++++++++++++
2 files changed, 55 insertions(+)
create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch
diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc
index 063c6cc2a43..5534ce577f9 100644
--- a/meta/recipes-devtools/binutils/binutils-2.42.inc
+++ b/meta/recipes-devtools/binutils/binutils-2.42.inc
@@ -79,5 +79,6 @@ SRC_URI = "\
file://CVE-2026-6846.patch \
file://CVE-2025-69645.patch \
file://CVE-2025-1147.patch \
+ file://CVE-2025-8224.patch \
"
S = "${WORKDIR}/git"
diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch b/meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch
new file mode 100644
index 00000000000..914b9084c27
--- /dev/null
+++ b/meta/recipes-devtools/binutils/binutils/CVE-2025-8224.patch
@@ -0,0 +1,54 @@
+From db856d41004301b3a56438efd957ef5cabb91530 Mon Sep 17 00:00:00 2001
+From: Alan Modra <amodra@gmail.com>
+Date: Sun, 25 Aug 2024 15:20:21 +0930
+Subject: [PATCH] PR32109, aborting at bfd/bfd.c:1236 in int _bfd_doprnt
+
+Since bfd_section for .strtab isn't set, print the section index
+instead. Also, don't return NULL on this error as that results in
+multiple mmap/read of the string table. (We could return NULL if we
+arranged to set sh_size zero first, but just what we do with fuzzed
+object files is of no concern, and terminating the table might make a
+faulty object file usable.)
+
+ PR 32109
+ * elf.c (bfd_elf_get_str_section): Remove outdated comment, and
+ tweak shstrtabsize test to suit. Don't use string tab bfd_section
+ in error message, use index instead. Don't return NULL on
+ unterminated string section, terminate it.
+ (_bfd_elf_get_dynamic_symbols): Similarly terminate string table
+ section.
+
+[Backport note: Adapted for binutils 2.42. The upstream commit targets
+a newer codebase that uses _bfd_mmap_readonly_persistent and has an
+explicit unterminated-string error path with return NULL. In 2.42 the
+code uses _bfd_alloc_and_read with shstrtabsize+1 allocation and
+unconditionally null-terminates via shstrtab[shstrtabsize] = '\0'.
+Only the shstrtabsize overflow check fix applies here (shstrtabsize + 1 <= 1
+changed to shstrtabsize == 0). The second upstream hunk (DT_STRTAB
+error_return -> terminate) does not apply as 2.42 already
+unconditionally null-terminates the dynamic string table.]
+
+CVE: CVE-2025-8224
+Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=db856d41004301b3a56438efd957ef5cabb91530]
+
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ bfd/elf.c | 4 +---
+ 1 file changed, 1 insertion(+), 3 deletions(-)
+
+diff --git a/bfd/elf.c b/bfd/elf.c
+--- a/bfd/elf.c
++++ b/bfd/elf.c
+@@ -285,9 +285,7 @@ bfd_elf_get_str_section (bfd *abfd, unsigned int shindex)
+ offset = i_shdrp[shindex]->sh_offset;
+ shstrtabsize = i_shdrp[shindex]->sh_size;
+
+- /* Allocate and clear an extra byte at the end, to prevent crashes
+- in case the string table is not terminated. */
+- if (shstrtabsize + 1 <= 1
++ if (shstrtabsize == 0
+ || bfd_seek (abfd, offset, SEEK_SET) != 0
+ || (shstrtab = _bfd_alloc_and_read (abfd, shstrtabsize + 1,
+ shstrtabsize)) == NULL)
+--
+2.43.7
^ permalink raw reply related [flat|nested] 25+ messages in thread* [OE-core][scarthgap 04/11] binutils: fix CVE-2026-15003
2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
` (2 preceding siblings ...)
2026-08-25 10:06 ` [OE-core][scarthgap 03/11] binutils: fix CVE-2025-8224 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 05/11] binutils: fix CVE-2026-18220 Yoann Congal
` (6 subsequent siblings)
10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-15003
https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=23acf2f003f81b2f8d9d1997ea45d822d33d386c
Test results:
binutils-cross-testsuite 2.42 (x86_64-oe-linux):
Before:
binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported
gas: 1871 passed, 4 unexpected failures, 2 unsupported
ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported
After:
binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported
gas: 1871 passed, 4 unexpected failures, 2 unsupported
ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported
Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=23acf2f003f81b2f8d9d1997ea45d822d33d386c]
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
.../binutils/binutils-2.42.inc | 1 +
.../binutils/binutils/CVE-2026-15003.patch | 400 ++++++++++++++++++
2 files changed, 401 insertions(+)
create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch
diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc
index 5534ce577f9..447529ffa95 100644
--- a/meta/recipes-devtools/binutils/binutils-2.42.inc
+++ b/meta/recipes-devtools/binutils/binutils-2.42.inc
@@ -80,5 +80,6 @@ SRC_URI = "\
file://CVE-2025-69645.patch \
file://CVE-2025-1147.patch \
file://CVE-2025-8224.patch \
+ file://CVE-2026-15003.patch \
"
S = "${WORKDIR}/git"
diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch b/meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch
new file mode 100644
index 00000000000..2f5c42e1b93
--- /dev/null
+++ b/meta/recipes-devtools/binutils/binutils/CVE-2026-15003.patch
@@ -0,0 +1,400 @@
+From 23acf2f003f81b2f8d9d1997ea45d822d33d386c Mon Sep 17 00:00:00 2001
+From: Alan Modra <amodra@gmail.com>
+Date: Thu, 9 Apr 2026 09:06:27 +0930
+Subject: [PATCH] PR 34053 buffer overflow in xcoff_link_add_symbols
+
+This patch adds two sanity checks with error reporting in
+xcoff_link_add_symbols before reading symbol aux entries, add extends
+assertions in later functions. A whole lot of unnecessary casts are
+also tidied.
+
+ PR 34053
+ * xcofflink.c: Remove unnecessary casts throughout.
+ (xcoff_link_add_symbols): Sanity check aux entries are within
+ symbol buffer.
+ (bfd_xcoff_build_dynamic_sections): Assert the above is true.
+ (xcoff_link_input_bfd): Likewise.
+
+CVE: CVE-2026-15003
+Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=23acf2f003f81b2f8d9d1997ea45d822d33d386c]
+
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ bfd/xcofflink.c | 132 +++++++++++++++++++++++-------------------------
+ 1 file changed, 62 insertions(+), 70 deletions(-)
+
+diff --git a/bfd/xcofflink.c b/bfd/xcofflink.c
+index 7f1c0df760f..cf3b33e7202 100644
+--- a/bfd/xcofflink.c
++++ b/bfd/xcofflink.c
+@@ -371,7 +371,7 @@ _bfd_xcoff_canonicalize_dynamic_symtab (bfd *abfd, asymbol **psyms)
+ {
+ char *c;
+
+- c = bfd_alloc (abfd, (bfd_size_type) SYMNMLEN + 1);
++ c = bfd_alloc (abfd, SYMNMLEN + 1);
+ if (c == NULL)
+ return -1;
+ memcpy (c, ldsym._l._l_name, SYMNMLEN);
+@@ -1038,7 +1038,7 @@ xcoff_link_add_dynamic_symbols (bfd *abfd, struct bfd_link_info *info)
+ {
+ char *dsnm;
+
+- dsnm = bfd_malloc ((bfd_size_type) strlen (name) + 2);
++ dsnm = bfd_malloc (strlen (name) + 2);
+ if (dsnm == NULL)
+ return false;
+ dsnm[0] = '.';
+@@ -1081,7 +1081,7 @@ xcoff_link_add_dynamic_symbols (bfd *abfd, struct bfd_link_info *info)
+ coff_section_data (abfd, lsec)->contents = NULL;
+
+ /* Record this file in the import files. */
+- n = bfd_alloc (abfd, (bfd_size_type) sizeof (struct xcoff_import_file));
++ n = bfd_alloc (abfd, sizeof (*n));
+ if (n == NULL)
+ return false;
+ n->next = NULL;
+@@ -1477,7 +1477,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info)
+ bfd_vma value;
+ struct xcoff_link_hash_entry *set_toc;
+
+- bfd_coff_swap_sym_in (abfd, (void *) esym, (void *) &sym);
++ bfd_coff_swap_sym_in (abfd, esym, &sym);
+
+ /* In this pass we are only interested in symbols with csect
+ information. */
+@@ -1523,9 +1523,12 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info)
+ {
+ union internal_auxent auxlin;
+
+- bfd_coff_swap_aux_in (abfd, (void *) (esym + symesz),
++ if (symesz >= (size_t) (esym_end - esym))
++ goto badaux;
++
++ bfd_coff_swap_aux_in (abfd, esym + symesz,
+ sym.n_type, sym.n_sclass,
+- 0, sym.n_numaux, (void *) &auxlin);
++ 0, sym.n_numaux, &auxlin);
+
+ if (auxlin.x_sym.x_fcnary.x_fcn.x_lnnoptr != 0)
+ {
+@@ -1552,7 +1555,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info)
+
+ linpstart = (reloc_info[enclosing->target_index].linenos
+ + linoff);
+- bfd_coff_swap_lineno_in (abfd, (void *) linpstart, (void *) &lin);
++ bfd_coff_swap_lineno_in (abfd, linpstart, &lin);
+ if (lin.l_lnno == 0
+ && ((bfd_size_type) lin.l_addr.l_symndx
+ == ((esym
+@@ -1567,8 +1570,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info)
+ linp < linpend;
+ linp += linesz)
+ {
+- bfd_coff_swap_lineno_in (abfd, (void *) linp,
+- (void *) &lin);
++ bfd_coff_swap_lineno_in (abfd, linp, &lin);
+ if (lin.l_lnno == 0)
+ break;
+ }
+@@ -1589,21 +1591,21 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info)
+ visibility = sym.n_type & SYM_V_MASK;
+
+ /* Pick up the csect auxiliary information. */
+- if (sym.n_numaux == 0)
++ if (sym.n_numaux < 1
++ || sym.n_numaux * symesz >= (size_t) (esym_end - esym))
+ {
++ badaux:
+ _bfd_error_handler
+ /* xgettext:c-format */
+- (_("%pB: class %d symbol `%s' has no aux entries"),
++ (_("%pB: class %d symbol '%s' has missing aux entries"),
+ abfd, sym.n_sclass, name);
+ bfd_set_error (bfd_error_bad_value);
+ goto error_return;
+ }
+
+- bfd_coff_swap_aux_in (abfd,
+- (void *) (esym + symesz * sym.n_numaux),
++ bfd_coff_swap_aux_in (abfd, esym + symesz * sym.n_numaux,
+ sym.n_type, sym.n_sclass,
+- sym.n_numaux - 1, sym.n_numaux,
+- (void *) &aux);
++ sym.n_numaux - 1, sym.n_numaux, &aux);
+
+ smtyp = SMTYP_SMTYP (aux.x_csect.x_smtyp);
+
+@@ -1726,7 +1728,7 @@ xcoff_link_add_symbols (bfd *abfd, struct bfd_link_info *info)
+
+ erelsym = ((bfd_byte *) obj_coff_external_syms (abfd)
+ + rel->r_symndx * symesz);
+- bfd_coff_swap_sym_in (abfd, (void *) erelsym, (void *) &relsym);
++ bfd_coff_swap_sym_in (abfd, erelsym, &relsym);
+ if (EXTERN_SYM_P (relsym.n_sclass))
+ {
+ const char *relname;
+@@ -2507,7 +2509,7 @@ xcoff_link_check_ar_symbols (bfd *abfd,
+ {
+ struct internal_syment sym;
+
+- bfd_coff_swap_sym_in (abfd, (void *) esym, (void *) &sym);
++ bfd_coff_swap_sym_in (abfd, esym, &sym);
+ esym += (sym.n_numaux + 1) * symesz;
+
+ if (EXTERN_SYM_P (sym.n_sclass) && sym.n_scnum != N_UNDEF)
+@@ -4005,7 +4007,7 @@ bfd_xcoff_size_dynamic_sections (bfd *output_bfd,
+ return true;
+
+ xcoff_link_hash_traverse (xcoff_hash_table (info), xcoff_post_gc_symbol,
+- (void *) ldinfo);
++ ldinfo);
+ if (ldinfo->failed)
+ goto error_return;
+
+@@ -4216,7 +4218,8 @@ bfd_xcoff_build_dynamic_sections (bfd *output_bfd,
+ /* Read in the csect information, if any. */
+ if (CSECT_SYM_P (sym.n_sclass))
+ {
+- BFD_ASSERT (sym.n_numaux > 0);
++ BFD_ASSERT (sym.n_numaux > 0
++ && symesz * sym.n_numaux < (size_t) (esymend - esym));
+ bfd_coff_swap_aux_in (sub, esym + symesz * sym.n_numaux,
+ sym.n_type, sym.n_sclass,
+ sym.n_numaux - 1, sym.n_numaux, &aux);
+@@ -4307,7 +4310,7 @@ bfd_xcoff_link_generate_rtinit (bfd *abfd,
+ {
+ struct bfd_in_memory *bim;
+
+- bim = bfd_malloc ((bfd_size_type) sizeof (* bim));
++ bim = bfd_malloc (sizeof (*bim));
+ if (bim == NULL)
+ return false;
+
+@@ -4316,7 +4319,7 @@ bfd_xcoff_link_generate_rtinit (bfd *abfd,
+
+ abfd->link.next = 0;
+ abfd->format = bfd_object;
+- abfd->iostream = (void *) bim;
++ abfd->iostream = bim;
+ abfd->flags = BFD_IN_MEMORY;
+ abfd->iovec = &_bfd_memory_iovec;
+ abfd->direction = write_direction;
+@@ -4876,8 +4879,8 @@ bfd_xcoff_size_stubs (struct bfd_link_info *info)
+ }
+
+ bfd_coff_swap_sym_in (input_bfd,
+- (void *) esyms + irel->r_symndx * symesz,
+- (void *) &sym);
++ esyms + irel->r_symndx * symesz,
++ &sym);
+
+ sym_sec = xcoff_data (input_bfd)->csects[irel->r_symndx];
+ sym_value = sym.n_value - sym_sec->vma;
+@@ -5250,17 +5253,16 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+ int smtyp = 0;
+ int add;
+
+- bfd_coff_swap_sym_in (input_bfd, (void *) esym, (void *) isymp);
++ bfd_coff_swap_sym_in (input_bfd, esym, isymp);
+
+ /* Read in the csect information, if any. */
+ if (CSECT_SYM_P (isymp->n_sclass))
+ {
+- BFD_ASSERT (isymp->n_numaux > 0);
+- bfd_coff_swap_aux_in (input_bfd,
+- (void *) (esym + isymesz * isymp->n_numaux),
++ BFD_ASSERT (isymp->n_numaux > 0
++ && isymesz * isymp->n_numaux < (size_t) (esym_end - esym));
++ bfd_coff_swap_aux_in (input_bfd, esym + isymesz * isymp->n_numaux,
+ isymp->n_type, isymp->n_sclass,
+- isymp->n_numaux - 1, isymp->n_numaux,
+- (void *) &aux);
++ isymp->n_numaux - 1, isymp->n_numaux, &aux);
+
+ smtyp = SMTYP_SMTYP (aux.x_csect.x_smtyp);
+ }
+@@ -5475,12 +5477,10 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+ if ((bfd_size_type) flinfo->last_file_index >= syment_base)
+ {
+ /* The last C_FILE symbol is in this input file. */
+- bfd_coff_swap_sym_out (output_bfd,
+- (void *) &flinfo->last_file,
+- (void *) (flinfo->outsyms
+- + ((flinfo->last_file_index
+- - syment_base)
+- * osymesz)));
++ bfd_coff_swap_sym_out
++ (output_bfd, &flinfo->last_file,
++ flinfo->outsyms + (flinfo->last_file_index
++ - syment_base) * osymesz);
+ }
+ else
+ {
+@@ -5489,9 +5489,8 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+ borrow *outsym temporarily. */
+ file_ptr pos;
+
+- bfd_coff_swap_sym_out (output_bfd,
+- (void *) &flinfo->last_file,
+- (void *) outsym);
++ bfd_coff_swap_sym_out (output_bfd, &flinfo->last_file,
++ outsym);
+
+ pos = obj_sym_filepos (output_bfd);
+ pos += flinfo->last_file_index * osymesz;
+@@ -5557,7 +5556,7 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+ }
+
+ /* Output the symbol. */
+- bfd_coff_swap_sym_out (output_bfd, (void *) &isym, (void *) outsym);
++ bfd_coff_swap_sym_out (output_bfd, &isym, outsym);
+
+ esym += isymesz;
+ outsym += osymesz;
+@@ -5566,9 +5565,9 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+ {
+ union internal_auxent aux;
+
+- bfd_coff_swap_aux_in (input_bfd, (void *) esym, isymp->n_type,
+- isymp->n_sclass, i, isymp->n_numaux,
+- (void *) &aux);
++ bfd_coff_swap_aux_in (input_bfd, esym,
++ isymp->n_type, isymp->n_sclass, i,
++ isymp->n_numaux, &aux);
+
+ if (isymp->n_sclass == C_FILE)
+ {
+@@ -5796,9 +5795,9 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+ }
+ }
+
+- bfd_coff_swap_aux_out (output_bfd, (void *) &aux, isymp->n_type,
++ bfd_coff_swap_aux_out (output_bfd, &aux, isymp->n_type,
+ isymp->n_sclass, i, isymp->n_numaux,
+- (void *) outsym);
++ outsym);
+ outsym += osymesz;
+ esym += isymesz;
+ }
+@@ -5820,10 +5819,9 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+ && (bfd_size_type) flinfo->last_file_index >= syment_base)
+ {
+ flinfo->last_file.n_value = output_index;
+- bfd_coff_swap_sym_out (output_bfd, (void *) &flinfo->last_file,
+- (void *) (flinfo->outsyms
+- + ((flinfo->last_file_index - syment_base)
+- * osymesz)));
++ bfd_coff_swap_sym_out (output_bfd, &flinfo->last_file,
++ flinfo->outsyms + (flinfo->last_file_index
++ - syment_base) * osymesz);
+ }
+
+ /* Write the modified symbols to the output file. */
+@@ -6036,16 +6034,13 @@ xcoff_link_input_bfd (struct xcoff_final_link_info *flinfo,
+ void * auxptr;
+ union internal_auxent aux;
+
+- auxptr = ((void *)
+- (((bfd_byte *)
+- obj_coff_external_syms (input_bfd))
+- + ((r_symndx + is->n_numaux)
+- * isymesz)));
++ auxptr = ((bfd_byte *)
++ obj_coff_external_syms (input_bfd)
++ + (r_symndx + is->n_numaux) * isymesz);
+ bfd_coff_swap_aux_in (input_bfd, auxptr,
+ is->n_type, is->n_sclass,
+ is->n_numaux - 1,
+- is->n_numaux,
+- (void *) &aux);
++ is->n_numaux, &aux);
+ if (SMTYP_SMTYP (aux.x_csect.x_smtyp) == XTY_SD
+ && aux.x_csect.x_smclas == XMC_TC0)
+ indx = flinfo->toc_symindx;
+@@ -6564,12 +6559,12 @@ xcoff_write_global_symbol (struct bfd_hash_entry *bh, void * inf)
+ irsym.n_type = T_NULL;
+ irsym.n_numaux = 1;
+
+- bfd_coff_swap_sym_out (output_bfd, (void *) &irsym, (void *) outsym);
++ bfd_coff_swap_sym_out (output_bfd, &irsym, outsym);
+ outsym += bfd_coff_symesz (output_bfd);
+
+ /* Note : iraux is initialized above. */
+- bfd_coff_swap_aux_out (output_bfd, (void *) &iraux, T_NULL, C_HIDEXT,
+- 0, 1, (void *) outsym);
++ bfd_coff_swap_aux_out (output_bfd, &iraux, T_NULL, C_HIDEXT,
++ 0, 1, outsym);
+ outsym += bfd_coff_auxesz (output_bfd);
+
+ if (h->indx >= 0)
+@@ -6807,12 +6802,11 @@ xcoff_write_global_symbol (struct bfd_hash_entry *bh, void * inf)
+ isym.n_type = T_NULL;
+ isym.n_numaux = 1;
+
+- bfd_coff_swap_sym_out (output_bfd, (void *) &isym, (void *) outsym);
++ bfd_coff_swap_sym_out (output_bfd, &isym, outsym);
+ outsym += bfd_coff_symesz (output_bfd);
+
+ aux.x_csect.x_smclas = h->smclas;
+- bfd_coff_swap_aux_out (output_bfd, (void *) &aux, T_NULL, isym.n_sclass, 0, 1,
+- (void *) outsym);
++ bfd_coff_swap_aux_out (output_bfd, &aux, T_NULL, isym.n_sclass, 0, 1, outsym);
+ outsym += bfd_coff_auxesz (output_bfd);
+
+ if ((h->root.type == bfd_link_hash_defined
+@@ -6827,13 +6821,12 @@ xcoff_write_global_symbol (struct bfd_hash_entry *bh, void * inf)
+ isym.n_sclass = C_WEAKEXT;
+ else
+ isym.n_sclass = C_EXT;
+- bfd_coff_swap_sym_out (output_bfd, (void *) &isym, (void *) outsym);
++ bfd_coff_swap_sym_out (output_bfd, &isym, outsym);
+ outsym += bfd_coff_symesz (output_bfd);
+
+ aux.x_csect.x_smtyp = XTY_LD;
+ aux.x_csect.x_scnlen.u64 = obj_raw_syment_count (output_bfd);
+- bfd_coff_swap_aux_out (output_bfd, (void *) &aux, T_NULL, C_EXT, 0, 1,
+- (void *) outsym);
++ bfd_coff_swap_aux_out (output_bfd, &aux, T_NULL, C_EXT, 0, 1, outsym);
+ outsym += bfd_coff_auxesz (output_bfd);
+ }
+
+@@ -6929,8 +6922,8 @@ xcoff_reloc_link_order (bfd *output_bfd,
+ howto->name, addend, NULL, NULL, (bfd_vma) 0);
+ break;
+ }
+- ok = bfd_set_section_contents (output_bfd, output_section, (void *) buf,
+- (file_ptr) link_order->offset, size);
++ ok = bfd_set_section_contents (output_bfd, output_section, buf,
++ link_order->offset, size);
+ free (buf);
+ if (! ok)
+ return false;
+@@ -7395,8 +7388,7 @@ _bfd_xcoff_bfd_final_link (bfd *abfd, struct bfd_link_info *info)
+ if (flinfo.last_file_index != -1)
+ {
+ flinfo.last_file.n_value = -(bfd_vma) 1;
+- bfd_coff_swap_sym_out (abfd, (void *) &flinfo.last_file,
+- (void *) flinfo.outsyms);
++ bfd_coff_swap_sym_out (abfd, &flinfo.last_file, flinfo.outsyms);
+ pos = obj_sym_filepos (abfd) + flinfo.last_file_index * symesz;
+ if (bfd_seek (abfd, pos, SEEK_SET) != 0
+ || bfd_write (flinfo.outsyms, symesz, abfd) != symesz)
+@@ -7480,7 +7472,7 @@ _bfd_xcoff_bfd_final_link (bfd *abfd, struct bfd_link_info *info)
+ appear in the symbol table, which is not necessarily by
+ address. So we sort them here. There may be a better way to
+ do this. */
+- qsort ((void *) flinfo.section_info[o->target_index].relocs,
++ qsort (flinfo.section_info[o->target_index].relocs,
+ o->reloc_count, sizeof (struct internal_reloc),
+ xcoff_sort_relocs);
+
+@@ -7488,7 +7480,7 @@ _bfd_xcoff_bfd_final_link (bfd *abfd, struct bfd_link_info *info)
+ irelend = irel + o->reloc_count;
+ erel = external_relocs;
+ for (; irel < irelend; irel++, rel_hash++, erel += relsz)
+- bfd_coff_swap_reloc_out (abfd, (void *) irel, (void *) erel);
++ bfd_coff_swap_reloc_out (abfd, irel, erel);
+
+ rel_size = relsz * o->reloc_count;
+ if (bfd_seek (abfd, o->rel_filepos, SEEK_SET) != 0
^ permalink raw reply related [flat|nested] 25+ messages in thread* [OE-core][scarthgap 05/11] binutils: fix CVE-2026-18220
2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
` (3 preceding siblings ...)
2026-08-25 10:06 ` [OE-core][scarthgap 04/11] binutils: fix CVE-2026-15003 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 06/11] libssh2: fix CVE-2026-58050 Yoann Congal
` (5 subsequent siblings)
10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
To: openembedded-core
From: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2026-18220
https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=114e3aae2b7e34057c8909301eaf78c15687e8e5
Test results:
binutils-cross-testsuite 2.42 (x86_64-oe-linux):
Before:
binutils: 302 passed, 2 unexpected failures, 1 untested, 7 unsupported
gas: 1871 passed, 4 unexpected failures, 2 unsupported
ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported
After:
binutils: 304 passed, 2 unexpected failures, 1 untested, 7 unsupported
gas: 1871 passed, 4 unexpected failures, 2 unsupported
ld: 1728 passed, 5 unexpected failures, 7 expected failures, 1 unresolved, 20 untested, 99 unsupported
Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=114e3aae2b7e34057c8909301eaf78c15687e8e5]
Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
.../binutils/binutils-2.42.inc | 1 +
.../binutils/binutils/CVE-2026-18220.patch | 65 +++++++++++++++++++
2 files changed, 66 insertions(+)
create mode 100644 meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch
diff --git a/meta/recipes-devtools/binutils/binutils-2.42.inc b/meta/recipes-devtools/binutils/binutils-2.42.inc
index 447529ffa95..d395ae1b1e0 100644
--- a/meta/recipes-devtools/binutils/binutils-2.42.inc
+++ b/meta/recipes-devtools/binutils/binutils-2.42.inc
@@ -81,5 +81,6 @@ SRC_URI = "\
file://CVE-2025-1147.patch \
file://CVE-2025-8224.patch \
file://CVE-2026-15003.patch \
+ file://CVE-2026-18220.patch \
"
S = "${WORKDIR}/git"
diff --git a/meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch b/meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch
new file mode 100644
index 00000000000..e915fb223a1
--- /dev/null
+++ b/meta/recipes-devtools/binutils/binutils/CVE-2026-18220.patch
@@ -0,0 +1,65 @@
+From 114e3aae2b7e34057c8909301eaf78c15687e8e5 Mon Sep 17 00:00:00 2001
+From: Alan Modra <amodra@gmail.com>
+Date: Sun, 28 Jun 2026 09:11:46 +0930
+Subject: [PATCH] asan: buffer overflow in elf32_dlx_relocate26
+
+ * elf32-dlx.c (elf32_dlx_relocate26): Sanity check reloc offset.
+ (elf32_dlx_relocate16): Likewise.
+ (_bfd_dlx_elf_hi16_reloc): Likewise, and remove ineffective
+ existing check.
+
+CVE: CVE-2026-18220
+Upstream-Status: Backport [https://sourceware.org/git/?p=binutils-gdb.git;a=commitdiff;h=114e3aae2b7e34057c8909301eaf78c15687e8e5]
+
+Signed-off-by: Jaipaul Cheernam <jaipaul.cheernam@est.tech>
+---
+ bfd/elf32-dlx.c | 15 ++++++++++++---
+ 1 file changed, 12 insertions(+), 3 deletions(-)
+
+diff --git a/bfd/elf32-dlx.c b/bfd/elf32-dlx.c
+index 2dfeb4d7390..0f9a49695d7 100644
+--- a/bfd/elf32-dlx.c
++++ b/bfd/elf32-dlx.c
+@@ -77,6 +77,10 @@ _bfd_dlx_elf_hi16_reloc (bfd *abfd,
+ return bfd_reloc_ok;
+ }
+
++ if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd,
++ input_section, reloc_entry->address))
++ return bfd_reloc_outofrange;
++
+ ret = bfd_reloc_ok;
+
+ if (bfd_is_und_section (symbol->section)
+@@ -89,9 +93,6 @@ _bfd_dlx_elf_hi16_reloc (bfd *abfd,
+ relocation += reloc_entry->addend;
+ relocation += bfd_get_16 (abfd, (bfd_byte *)data + reloc_entry->address);
+
+- if (reloc_entry->address > bfd_get_section_limit (abfd, input_section))
+- return bfd_reloc_outofrange;
+-
+ bfd_put_16 (abfd, (short)((relocation >> 16) & 0xFFFF),
+ (bfd_byte *)data + reloc_entry->address);
+
+@@ -143,6 +144,10 @@ elf32_dlx_relocate16 (bfd *abfd,
+ return bfd_reloc_undefined;
+ }
+
++ if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd,
++ input_section, reloc_entry->address))
++ return bfd_reloc_outofrange;
++
+ insn = bfd_get_32 (abfd, (bfd_byte *)data + reloc_entry->address);
+ allignment = 1 << (input_section->output_section->alignment_power - 1);
+ vallo = insn & 0x0000FFFF;
+@@ -206,6 +211,10 @@ elf32_dlx_relocate26 (bfd *abfd,
+ return bfd_reloc_undefined;
+ }
+
++ if (!bfd_reloc_offset_in_range (reloc_entry->howto, abfd,
++ input_section, reloc_entry->address))
++ return bfd_reloc_outofrange;
++
+ insn = bfd_get_32 (abfd, (bfd_byte *)data + reloc_entry->address);
+ allignment = 1 << (input_section->output_section->alignment_power - 1);
+ vallo = insn & 0x03FFFFFF;
^ permalink raw reply related [flat|nested] 25+ messages in thread* [OE-core][scarthgap 06/11] libssh2: fix CVE-2026-58050
2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
` (4 preceding siblings ...)
2026-08-25 10:06 ` [OE-core][scarthgap 05/11] binutils: fix CVE-2026-18220 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 07/11] glib-2.0: fix CVE-2026-58015 Yoann Congal
` (4 subsequent siblings)
10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
To: openembedded-core
From: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
Backport patch to fix CVE-2026-58050.
References:
https://nvd.nist.gov/vuln/detail/CVE-2026-58050
Upstream fix:
https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12
Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
.../libssh2/libssh2/CVE-2026-58050.patch | 45 +++++++++++++++++++
.../recipes-support/libssh2/libssh2_1.11.1.bb | 1 +
2 files changed, 46 insertions(+)
create mode 100644 meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch
diff --git a/meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch b/meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch
new file mode 100644
index 00000000000..0163b379f35
--- /dev/null
+++ b/meta/recipes-support/libssh2/libssh2/CVE-2026-58050.patch
@@ -0,0 +1,45 @@
+From 05b2fb4ec89d75235dbd97c5965dc0e46b405a7c Mon Sep 17 00:00:00 2001
+From: Viktor Szakats <commit@vsz.me>
+Date: Sun, 28 Jun 2026 02:12:52 +0200
+Subject: [PATCH] publickey: fix potential multiplication overflow in 32-bit
+ `libssh2_publickey_list_fetch()`
+
+Cap list size at 1024 elements.
+
+Reported-and-initial-patch-by: Mateusz Gierblinski
+Reported-and-initial-patch-by: Behzod Abdullayev
+Reported-by: Sharique Raza
+
+Follow-up to e15f5d97a04cc676ce117dd324fef85b046207a9
+
+Closes #2128
+
+src/publickey.c: replaced ssh2_err() with _libssh2_error() to match
+the stable branch's error-reporting convention.
+
+Assisted-by: kiro:claude-sonnet-5
+
+CVE: CVE-2026-58050
+Upstream-Status: Backport [https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12]
+
+Signed-off-by: Adarsh Jagadish Kamini <adarsh.jagadish.kamini@est.tech>
+---
+ src/publickey.c | 5 +++++
+ 1 file changed, 5 insertions(+)
+
+diff --git a/src/publickey.c b/src/publickey.c
+index 9c9fa618..196d2f9f 100644
+--- a/src/publickey.c
++++ b/src/publickey.c
+@@ -1114,6 +1114,11 @@ libssh2_publickey_list_fetch(LIBSSH2_PUBLICKEY * pkey, unsigned long *num_keys,
+ }
+
+ if(list[keys].num_attrs) {
++ if(list[keys].num_attrs > 1024) {
++ _libssh2_error(session, LIBSSH2_ERROR_OUT_OF_BOUNDARY,
++ "Too many publickey attributes");
++ goto err_exit;
++ }
+ list[keys].attrs =
+ LIBSSH2_ALLOC(session,
+ list[keys].num_attrs *
diff --git a/meta/recipes-support/libssh2/libssh2_1.11.1.bb b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
index d14a27f3dc3..d3f39050474 100644
--- a/meta/recipes-support/libssh2/libssh2_1.11.1.bb
+++ b/meta/recipes-support/libssh2/libssh2_1.11.1.bb
@@ -20,6 +20,7 @@ SRC_URI = "http://www.libssh2.org/download/${BP}.tar.gz \
file://CVE-2026-66033.patch \
file://CVE-2026-66034.patch \
file://CVE-2026-66035.patch \
+ file://CVE-2026-58050.patch \
"
SRC_URI[sha256sum] = "d9ec76cbe34db98eec3539fe2c899d26b0c837cb3eb466a56b0f109cabf658f7"
^ permalink raw reply related [flat|nested] 25+ messages in thread* [OE-core][scarthgap 07/11] glib-2.0: fix CVE-2026-58015
2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
` (5 preceding siblings ...)
2026-08-25 10:06 ` [OE-core][scarthgap 06/11] libssh2: fix CVE-2026-58050 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 08/11] curl: fix CVE-2025-10148 backport for websockets on 8.7.1 Yoann Congal
` (3 subsequent siblings)
10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
To: openembedded-core
From: Deepak Rathore <deeratho@cisco.com>
This patch applies the upstream glib-2-88 stable backport chain for
CVE-2026-58015. The issue is in the D-Bus SHA-1 authentication
mechanism, where a malicious peer could provide an unchecked cookie
context and cause the client to access unintended files while resolving
the cookie challenge.
Backport the upstream GLib fix chain from the glib-2-88 stable branch:
- db9c8fae398b validates cookie_context before keyring lookup. This is
the primary security fix for CVE-2026-58015 [1].
- c0531125344b tightens cookie ID parsing so empty, negative, and
out-of-range values are rejected. This hardens the same SHA-1 cookie
challenge parser and is covered by the upstream regression test [2].
- 060aea67de75 exposes the private client reject-reason vfunc. This is
test-support plumbing required by the upstream regression test [3].
- 091930196229 adds the upstream regression test for SHA-1 cookie
challenge parsing [4].
Add dbus-native to PACKAGECONFIG[tests] so Meson can find dbus-daemon
when building the new installed D-Bus regression test for ptest. This is
kept as a native-only test dependency to avoid adding a target dbus
dependency to glib.
[1] https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a
[2] https://gitlab.gnome.org/GNOME/glib/-/commit/c0531125344bb25fd66ffb7435ed6c285de09aeb
[3] https://gitlab.gnome.org/GNOME/glib/-/commit/060aea67de7517d531b8fe2cdc07aa1a00ddeb22
[4] https://gitlab.gnome.org/GNOME/glib/-/commit/0919301962291a712067ee0c5d273cc392f33277
[5] https://nvd.nist.gov/vuln/detail/CVE-2026-58015
Signed-off-by: Deepak Rathore <deeratho@cisco.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
.../glib-2.0/glib-2.0/CVE-2026-58015_p1.patch | 97 ++++++++
.../glib-2.0/glib-2.0/CVE-2026-58015_p2.patch | 55 +++++
.../glib-2.0/glib-2.0/CVE-2026-58015_p3.patch | 198 ++++++++++++++++
.../glib-2.0/glib-2.0/CVE-2026-58015_p4.patch | 222 ++++++++++++++++++
meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb | 4 +
meta/recipes-core/glib-2.0/glib.inc | 2 +-
6 files changed, 577 insertions(+), 1 deletion(-)
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch
create mode 100644 meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch
new file mode 100644
index 00000000000..1216e1a12b1
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p1.patch
@@ -0,0 +1,97 @@
+From 1d0d0dc891399e8572a6c96b116149d076e2de28 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 15:47:30 +0100
+Subject: [PATCH 1/4] gdbusauthmechanismsha1: Validate cookie context
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+Without validation, the server could send a malicious context which
+contains path traversal characters, allowing it to exfiltrate a SHA-1
+hashed copy of arbitrary data from the client’s file system.
+
+To exploit this successfully would require the client to choose to
+connect peer-to-peer to a malicious D-Bus server and to choose the SHA-1
+authentication mechanism in preference to all the other mechanisms. This
+is vanishingly unlikely.
+
+CVE: CVE-2026-58015
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/db9c8fae398b0c457e660ce63dd5afec8993046a]
+
+Backport Changes:
+- Added <stdint.h> include because the target branch does not otherwise
+ expose uint8_t used by the upstream validation code during native builds.
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+
+Fixes: #3931
+(cherry picked from commit db9c8fae398b0c457e660ce63dd5afec8993046a)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ gio/gdbusauthmechanismsha1.c | 37 ++++++++++++++++++++++++++++++++++++
+ 1 file changed, 37 insertions(+)
+
+diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c
+index c8aa08977..7d8fc1922 100644
+--- a/gio/gdbusauthmechanismsha1.c
++++ b/gio/gdbusauthmechanismsha1.c
+@@ -22,6 +22,7 @@
+
+ #include "config.h"
+
++#include <stdint.h>
+ #include <string.h>
+ #include <fcntl.h>
+ #include <errno.h>
+@@ -1198,6 +1199,34 @@ mechanism_client_initiate (GDBusAuthMechanism *mechanism,
+ return initial_response;
+ }
+
++/* Context names must be valid ASCII, nonzero length, and may not contain the
++ * characters slash ("/"), backslash ("\"), space (" "), newline ("\n"),
++ * carriage return ("\r"), tab ("\t"), or period (".").
++ *
++ * See https://dbus.freedesktop.org/doc/dbus-specification.html#auth-mechanisms-sha */
++static gboolean
++validate_cookie_context (const char *cookie_context)
++{
++ size_t i = 0;
++
++ g_return_val_if_fail (cookie_context != NULL, FALSE);
++
++ for (i = 0; cookie_context[i] != '\0'; i++)
++ {
++ if ((uint8_t) cookie_context[i] >= 128 ||
++ cookie_context[i] == '/' ||
++ cookie_context[i] == '\\' ||
++ cookie_context[i] == ' ' ||
++ cookie_context[i] == '\n' ||
++ cookie_context[i] == '\r' ||
++ cookie_context[i] == '\t' ||
++ cookie_context[i] == '.')
++ return FALSE;
++ }
++
++ return (i > 0);
++}
++
+ static void
+ mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
+ const gchar *data,
+@@ -1232,6 +1261,14 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
+ }
+
+ cookie_context = tokens[0];
++ if (!validate_cookie_context (tokens[0]))
++ {
++ g_free (m->priv->reject_reason);
++ m->priv->reject_reason = g_strdup_printf ("Malformed cookie_context '%s'", tokens[0]);
++ m->priv->state = G_DBUS_AUTH_MECHANISM_STATE_REJECTED;
++ goto out;
++ }
++
+ cookie_id = g_ascii_strtoll (tokens[1], &endp, 10);
+ if (*endp != '\0')
+ {
+--
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch
new file mode 100644
index 00000000000..28f496734a5
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p2.patch
@@ -0,0 +1,55 @@
+From a94b2df7e2bc5f49661e53c2781ce99ae48d18aa Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 15:49:54 +0100
+Subject: [PATCH 2/4] gdbusauthmechanismsha1: Improve validation of cookie ID
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+The D-Bus specification says the cookie ID has to be non-negative, but
+we weren’t checking that (or checking that it was non-empty).
+
+CVE: CVE-2026-58015
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/c0531125344bb25fd66ffb7435ed6c285de09aeb]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit c0531125344bb25fd66ffb7435ed6c285de09aeb)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ gio/gdbusauthmechanismsha1.c | 6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c
+index 7d8fc1922..e753d139d 100644
+--- a/gio/gdbusauthmechanismsha1.c
++++ b/gio/gdbusauthmechanismsha1.c
+@@ -1235,7 +1235,7 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
+ GDBusAuthMechanismSha1 *m = G_DBUS_AUTH_MECHANISM_SHA1 (mechanism);
+ gchar **tokens;
+ const gchar *cookie_context;
+- guint cookie_id;
++ int64_t cookie_id;
+ const gchar *server_challenge;
+ gchar *client_challenge;
+ gchar *endp;
+@@ -1270,7 +1270,7 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
+ }
+
+ cookie_id = g_ascii_strtoll (tokens[1], &endp, 10);
+- if (*endp != '\0')
++ if (*endp != '\0' || endp == tokens[1] || cookie_id < 0 || cookie_id > UINT32_MAX)
+ {
+ g_free (m->priv->reject_reason);
+ m->priv->reject_reason = g_strdup_printf ("Malformed cookie_id '%s'", tokens[1]);
+@@ -1280,7 +1280,7 @@ mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
+ server_challenge = tokens[2];
+
+ error = NULL;
+- cookie = keyring_lookup_entry (cookie_context, cookie_id, &error);
++ cookie = keyring_lookup_entry (cookie_context, (unsigned int) cookie_id, &error);
+ if (cookie == NULL)
+ {
+ g_free (m->priv->reject_reason);
+--
+2.35.6
+
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch
new file mode 100644
index 00000000000..b6bd2baeb3f
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p3.patch
@@ -0,0 +1,198 @@
+From 99c7abffbd1d549f6c625de6f2028efcdeea5c49 Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 15:51:00 +0100
+Subject: [PATCH 3/4] gdbusauthmechanism: Expose client reject reason as a new
+ vfunc
+
+We can do this because `gdbusauthmechanism.h` is a private header.
+
+Hook it up to the existing `reject_reason` code in each
+`GDBusAuthMechanism` implementation, as all three implementations
+currently intermingle reject reasons from the server and client code, so
+there would currently be no benefit to having a separate server and
+client implementation of `*_get_reject_reason()`.
+
+This new private API will be used in a new unit test in the following
+commit.
+
+CVE: CVE-2026-58015
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/060aea67de7517d531b8fe2cdc07aa1a00ddeb22]
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+(cherry picked from commit 060aea67de7517d531b8fe2cdc07aa1a00ddeb22)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ gio/gdbusauthmechanism.c | 7 +++++++
+ gio/gdbusauthmechanism.h | 2 ++
+ gio/gdbusauthmechanismanon.c | 8 ++++----
+ gio/gdbusauthmechanismexternal.c | 8 ++++----
+ gio/gdbusauthmechanismsha1.c | 8 ++++----
+ 5 files changed, 21 insertions(+), 12 deletions(-)
+
+diff --git a/gio/gdbusauthmechanism.c b/gio/gdbusauthmechanism.c
+index 6e494dbd9..0d4ef4389 100644
+--- a/gio/gdbusauthmechanism.c
++++ b/gio/gdbusauthmechanism.c
+@@ -328,6 +328,13 @@ _g_dbus_auth_mechanism_client_data_send (GDBusAuthMechanism *mechanism,
+ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_data_send (mechanism, out_data_len);
+ }
+
++gchar *
++_g_dbus_auth_mechanism_client_get_reject_reason (GDBusAuthMechanism *mechanism)
++{
++ g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM (mechanism), NULL);
++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_get_reject_reason (mechanism);
++}
++
+ void
+ _g_dbus_auth_mechanism_client_shutdown (GDBusAuthMechanism *mechanism)
+ {
+diff --git a/gio/gdbusauthmechanism.h b/gio/gdbusauthmechanism.h
+index f0edd19a3..e906a47ac 100644
+--- a/gio/gdbusauthmechanism.h
++++ b/gio/gdbusauthmechanism.h
+@@ -100,6 +100,7 @@ struct _GDBusAuthMechanismClass
+ gsize data_len);
+ gchar *(*client_data_send) (GDBusAuthMechanism *mechanism,
+ gsize *out_data_len);
++ gchar *(*client_get_reject_reason) (GDBusAuthMechanism *mechanism);
+ void (*client_shutdown) (GDBusAuthMechanism *mechanism);
+ };
+
+@@ -148,6 +149,7 @@ void _g_dbus_auth_mechanism_client_data_receive (GDBus
+ gsize data_len);
+ gchar *_g_dbus_auth_mechanism_client_data_send (GDBusAuthMechanism *mechanism,
+ gsize *out_data_len);
++gchar *_g_dbus_auth_mechanism_client_get_reject_reason (GDBusAuthMechanism *mechanism);
+ void _g_dbus_auth_mechanism_client_shutdown (GDBusAuthMechanism *mechanism);
+
+
+diff --git a/gio/gdbusauthmechanismanon.c b/gio/gdbusauthmechanismanon.c
+index 5f59d4a61..3d80ec15f 100644
+--- a/gio/gdbusauthmechanismanon.c
++++ b/gio/gdbusauthmechanismanon.c
+@@ -56,7 +56,7 @@ static void mechanism_server_data_receive (GDBusAuthMe
+ gsize data_len);
+ static gchar *mechanism_server_data_send (GDBusAuthMechanism *mechanism,
+ gsize *out_data_len);
+-static gchar *mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism);
++static gchar *mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism);
+ static void mechanism_server_shutdown (GDBusAuthMechanism *mechanism);
+ static GDBusAuthMechanismState mechanism_client_get_state (GDBusAuthMechanism *mechanism);
+ static gchar *mechanism_client_initiate (GDBusAuthMechanism *mechanism,
+@@ -103,12 +103,13 @@ _g_dbus_auth_mechanism_anon_class_init (GDBusAuthMechanismAnonClass *klass)
+ mechanism_class->server_initiate = mechanism_server_initiate;
+ mechanism_class->server_data_receive = mechanism_server_data_receive;
+ mechanism_class->server_data_send = mechanism_server_data_send;
+- mechanism_class->server_get_reject_reason = mechanism_server_get_reject_reason;
++ mechanism_class->server_get_reject_reason = mechanism_server_or_client_get_reject_reason;
+ mechanism_class->server_shutdown = mechanism_server_shutdown;
+ mechanism_class->client_get_state = mechanism_client_get_state;
+ mechanism_class->client_initiate = mechanism_client_initiate;
+ mechanism_class->client_data_receive = mechanism_client_data_receive;
+ mechanism_class->client_data_send = mechanism_client_data_send;
++ mechanism_class->client_get_reject_reason = mechanism_server_or_client_get_reject_reason;
+ mechanism_class->client_shutdown = mechanism_client_shutdown;
+ }
+
+@@ -222,12 +223,11 @@ mechanism_server_data_send (GDBusAuthMechanism *mechanism,
+ }
+
+ static gchar *
+-mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism)
++mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism)
+ {
+ GDBusAuthMechanismAnon *m = G_DBUS_AUTH_MECHANISM_ANON (mechanism);
+
+ g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_ANON (mechanism), NULL);
+- g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, NULL);
+ g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_REJECTED, NULL);
+
+ /* can never end up here because we are never in the REJECTED state */
+diff --git a/gio/gdbusauthmechanismexternal.c b/gio/gdbusauthmechanismexternal.c
+index 6fe8b1bed..b223ead04 100644
+--- a/gio/gdbusauthmechanismexternal.c
++++ b/gio/gdbusauthmechanismexternal.c
+@@ -64,7 +64,7 @@ static void mechanism_server_data_receive (GDBusAuthMe
+ gsize data_len);
+ static gchar *mechanism_server_data_send (GDBusAuthMechanism *mechanism,
+ gsize *out_data_len);
+-static gchar *mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism);
++static gchar *mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism);
+ static void mechanism_server_shutdown (GDBusAuthMechanism *mechanism);
+ static GDBusAuthMechanismState mechanism_client_get_state (GDBusAuthMechanism *mechanism);
+ static gchar *mechanism_client_initiate (GDBusAuthMechanism *mechanism,
+@@ -111,12 +111,13 @@ _g_dbus_auth_mechanism_external_class_init (GDBusAuthMechanismExternalClass *kla
+ mechanism_class->server_initiate = mechanism_server_initiate;
+ mechanism_class->server_data_receive = mechanism_server_data_receive;
+ mechanism_class->server_data_send = mechanism_server_data_send;
+- mechanism_class->server_get_reject_reason = mechanism_server_get_reject_reason;
++ mechanism_class->server_get_reject_reason = mechanism_server_or_client_get_reject_reason;
+ mechanism_class->server_shutdown = mechanism_server_shutdown;
+ mechanism_class->client_get_state = mechanism_client_get_state;
+ mechanism_class->client_initiate = mechanism_client_initiate;
+ mechanism_class->client_data_receive = mechanism_client_data_receive;
+ mechanism_class->client_data_send = mechanism_client_data_send;
++ mechanism_class->client_get_reject_reason = mechanism_server_or_client_get_reject_reason;
+ mechanism_class->client_shutdown = mechanism_client_shutdown;
+ }
+
+@@ -321,12 +322,11 @@ mechanism_server_data_send (GDBusAuthMechanism *mechanism,
+ }
+
+ static gchar *
+-mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism)
++mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism)
+ {
+ GDBusAuthMechanismExternal *m = G_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism);
+
+ g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_EXTERNAL (mechanism), NULL);
+- g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, NULL);
+ g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_REJECTED, NULL);
+
+ /* can never end up here because we are never in the REJECTED state */
+diff --git a/gio/gdbusauthmechanismsha1.c b/gio/gdbusauthmechanismsha1.c
+index e753d139d..6c1682d3a 100644
+--- a/gio/gdbusauthmechanismsha1.c
++++ b/gio/gdbusauthmechanismsha1.c
+@@ -120,7 +120,7 @@ static void mechanism_server_data_receive (GDBusAuthMe
+ gsize data_len);
+ static gchar *mechanism_server_data_send (GDBusAuthMechanism *mechanism,
+ gsize *out_data_len);
+-static gchar *mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism);
++static gchar *mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism);
+ static void mechanism_server_shutdown (GDBusAuthMechanism *mechanism);
+ static GDBusAuthMechanismState mechanism_client_get_state (GDBusAuthMechanism *mechanism);
+ static gchar *mechanism_client_initiate (GDBusAuthMechanism *mechanism,
+@@ -173,12 +173,13 @@ _g_dbus_auth_mechanism_sha1_class_init (GDBusAuthMechanismSha1Class *klass)
+ mechanism_class->server_initiate = mechanism_server_initiate;
+ mechanism_class->server_data_receive = mechanism_server_data_receive;
+ mechanism_class->server_data_send = mechanism_server_data_send;
+- mechanism_class->server_get_reject_reason = mechanism_server_get_reject_reason;
++ mechanism_class->server_get_reject_reason = mechanism_server_or_client_get_reject_reason;
+ mechanism_class->server_shutdown = mechanism_server_shutdown;
+ mechanism_class->client_get_state = mechanism_client_get_state;
+ mechanism_class->client_initiate = mechanism_client_initiate;
+ mechanism_class->client_data_receive = mechanism_client_data_receive;
+ mechanism_class->client_data_send = mechanism_client_data_send;
++ mechanism_class->client_get_reject_reason = mechanism_server_or_client_get_reject_reason;
+ mechanism_class->client_shutdown = mechanism_client_shutdown;
+ }
+
+@@ -1129,12 +1130,11 @@ mechanism_server_data_send (GDBusAuthMechanism *mechanism,
+ }
+
+ static gchar *
+-mechanism_server_get_reject_reason (GDBusAuthMechanism *mechanism)
++mechanism_server_or_client_get_reject_reason (GDBusAuthMechanism *mechanism)
+ {
+ GDBusAuthMechanismSha1 *m = G_DBUS_AUTH_MECHANISM_SHA1 (mechanism);
+
+ g_return_val_if_fail (G_IS_DBUS_AUTH_MECHANISM_SHA1 (mechanism), NULL);
+- g_return_val_if_fail (m->priv->is_server && !m->priv->is_client, NULL);
+ g_return_val_if_fail (m->priv->state == G_DBUS_AUTH_MECHANISM_STATE_REJECTED, NULL);
+
+ return g_strdup (m->priv->reject_reason);
+--
+2.35.6
+
diff --git a/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch
new file mode 100644
index 00000000000..0785ad3c3a6
--- /dev/null
+++ b/meta/recipes-core/glib-2.0/glib-2.0/CVE-2026-58015_p4.patch
@@ -0,0 +1,222 @@
+From 80d2edcc14f476d0ec82dc0733964afa6e9ca74d Mon Sep 17 00:00:00 2001
+From: Philip Withnall <pwithnall@gnome.org>
+Date: Tue, 28 Apr 2026 15:52:53 +0100
+Subject: [PATCH 4/4] tests: Add a unit test for GDBusAuthMechanismSha1 cookie
+ context parsing
+
+This checks for regressions in the fixes from the previous few commits.
+
+CVE: CVE-2026-58015
+Upstream-Status: Backport [https://gitlab.gnome.org/GNOME/glib/-/commit/0919301962291a712067ee0c5d273cc392f33277]
+
+Backport Changes:
+- Replaced the literal U+1F600 test string with its UTF-8 byte escapes to
+ avoid the observed Patchwork mbox truncation. The test input is unchanged.
+
+Signed-off-by: Philip Withnall <pwithnall@gnome.org>
+Helps: #3931
+(cherry picked from commit 0919301962291a712067ee0c5d273cc392f33277)
+Signed-off-by: Deepak Rathore <deeratho@cisco.com>
+---
+ gio/tests/gdbus-auth-mechanism-sha1.c | 177 ++++++++++++++++++++++++++
+ gio/tests/meson.build | 1 +
+ 2 files changed, 178 insertions(+)
+ create mode 100644 gio/tests/gdbus-auth-mechanism-sha1.c
+
+diff --git a/gio/tests/gdbus-auth-mechanism-sha1.c b/gio/tests/gdbus-auth-mechanism-sha1.c
+new file mode 100644
+index 000000000..abcdb4e3e
+--- /dev/null
++++ b/gio/tests/gdbus-auth-mechanism-sha1.c
+@@ -0,0 +1,177 @@
++/* GLib testing framework examples and tests
++ *
++ * Copyright (C) 2026 Philip Withnall
++ *
++ * SPDX-License-Identifier: LGPL-2.1-or-later
++ *
++ * This library is free software; you can redistribute it and/or
++ * modify it under the terms of the GNU Lesser General Public
++ * License as published by the Free Software Foundation; either
++ * version 2.1 of the License, or (at your option) any later version.
++ *
++ * This library is distributed in the hope that it will be useful,
++ * but WITHOUT ANY WARRANTY; without even the implied warranty of
++ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
++ * Lesser General Public License for more details.
++ *
++ * You should have received a copy of the GNU Lesser General
++ * Public License along with this library; if not, see <http://www.gnu.org/licenses/>.
++ *
++ * Author: Philip Withnall <pwithnall@gnome.org>
++ */
++
++#include <locale.h>
++#include <gio/gio.h>
++
++#include <string.h>
++#include <unistd.h>
++
++#include "gdbus-tests.h"
++
++#ifdef G_OS_UNIX
++#include <gio/gunixconnection.h>
++#include <gio/gnetworkingprivate.h>
++#include <gio/gunixsocketaddress.h>
++#include <gio/gunixfdlist.h>
++#endif
++
++#define GIO_COMPILATION 1
++#include "gdbusauthmechanism.h"
++#include "gdbusauthmechanismsha1.h"
++
++/* Vfunc wrappers copied from gdbusauthmechanism.c as they are not public. */
++static gboolean
++dbus_auth_mechanism_is_supported (GDBusAuthMechanism *mechanism)
++{
++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->is_supported (mechanism);
++}
++
++static GDBusAuthMechanismState
++dbus_auth_mechanism_client_get_state (GDBusAuthMechanism *mechanism)
++{
++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_get_state (mechanism);
++}
++
++static gchar *
++dbus_auth_mechanism_client_initiate (GDBusAuthMechanism *mechanism,
++ GDBusConnectionFlags conn_flags,
++ size_t *out_initial_response_len)
++{
++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_initiate (mechanism,
++ conn_flags,
++ out_initial_response_len);
++}
++
++static void
++dbus_auth_mechanism_client_data_receive (GDBusAuthMechanism *mechanism,
++ const char *data,
++ size_t data_len)
++{
++ G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_data_receive (mechanism, data, data_len);
++}
++
++static char *
++dbus_auth_mechanism_client_get_reject_reason (GDBusAuthMechanism *mechanism)
++{
++ return G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_get_reject_reason (mechanism);
++}
++
++static void
++dbus_auth_mechanism_client_shutdown (GDBusAuthMechanism *mechanism)
++{
++ G_DBUS_AUTH_MECHANISM_GET_CLASS (mechanism)->client_shutdown (mechanism);
++}
++
++static void
++test_server_challenge_validation (void)
++{
++ const struct
++ {
++ const char *server_challenge;
++ const char *expected_reject_reason_prefix;
++ }
++ vectors[] = {
++ { "valid_context 123 456", "Problems looking up entry in keyring" },
++ { "invalid/context 123 456", "Malformed cookie_context" },
++ { "invalid.context 123 456", "Malformed cookie_context" },
++ { " 123 456", "Malformed cookie_context" },
++ { "\xF0\x9F\x98\x80" " 123 456", "Malformed cookie_context" },
++ { "invalid\ncontext 123 456", "Malformed cookie_context" },
++ { "invalid\rcontext 123 456", "Malformed cookie_context" },
++ { "invalid\tcontext 123 456", "Malformed cookie_context" },
++ { "invalid\\context 123 456", "Malformed cookie_context" },
++ { "valid_context 456", "Malformed cookie_id" },
++ { "valid_context 123notanumber 456", "Malformed cookie_id" },
++ { "valid_context -1 456", "Malformed cookie_id" },
++ { "valid_context 4294967296 456", "Malformed cookie_id" },
++ { "valid_context 123 ", "Malformed data" },
++ { "valid_context ", "Malformed data" },
++ };
++ GType mechanism_type;
++ GDBusConnection *connection = NULL;
++
++ g_test_summary ("Test that GDBusAuthMechanismSha1 rejects various malformed server data lines");
++
++ /* Briefly connect to the actual bus to ensure the GDBusAuth mechanisms are
++ * all registered. */
++ session_bus_up ();
++
++ connection = g_bus_get_sync (G_BUS_TYPE_SESSION, NULL, NULL);
++ g_assert_nonnull (connection);
++ g_clear_object (&connection);
++
++ session_bus_down ();
++
++ /* Check that we now have the type ID for GDBusAuthMechanismSha1 */
++ mechanism_type = g_type_from_name ("GDBusAuthMechanismSha1");
++ g_assert_cmpint (mechanism_type, !=, 0);
++
++ for (size_t i = 0; i < G_N_ELEMENTS (vectors); i++)
++ {
++ GDBusAuthMechanism *mechanism = NULL;
++ char *data = NULL;
++ size_t data_len = 0;
++ char *reject_reason = NULL;
++
++ mechanism = g_object_new (mechanism_type, NULL);
++
++ if (!dbus_auth_mechanism_is_supported (mechanism))
++ {
++ g_test_skip ("Mechanism not supported");
++ g_clear_object (&mechanism);
++ return;
++ }
++
++ data = dbus_auth_mechanism_client_initiate (mechanism,
++ G_DBUS_CONNECTION_FLAGS_AUTHENTICATION_CLIENT,
++ &data_len);
++ g_free (data);
++
++ dbus_auth_mechanism_client_data_receive (mechanism, vectors[i].server_challenge, strlen (vectors[i].server_challenge));
++
++ g_assert_cmpint (dbus_auth_mechanism_client_get_state (mechanism), ==, G_DBUS_AUTH_MECHANISM_STATE_REJECTED);
++
++ reject_reason = dbus_auth_mechanism_client_get_reject_reason (mechanism);
++ g_assert_true (g_str_has_prefix (reject_reason, vectors[i].expected_reject_reason_prefix));
++ g_free (reject_reason);
++
++ dbus_auth_mechanism_client_shutdown (mechanism);
++
++ g_clear_object (&mechanism);
++ }
++}
++
++int
++main (int argc,
++ char *argv[])
++{
++ setlocale (LC_ALL, "C");
++
++ g_test_init (&argc, &argv, G_TEST_OPTION_ISOLATE_DIRS, NULL);
++
++ g_test_dbus_unset ();
++
++ g_test_add_func ("/gdbus/auth-mechanism-sha1/server-challenge-validation", test_server_challenge_validation);
++
++ return g_test_run ();
++}
+diff --git a/gio/tests/meson.build b/gio/tests/meson.build
+index e7699c336..74ea481ff 100644
+--- a/gio/tests/meson.build
++++ b/gio/tests/meson.build
+@@ -418,6 +418,7 @@ if host_system != 'windows'
+ },
+ 'fdo-notification-backend': {},
+ 'gdbus-auth' : {'extra_sources' : extra_sources},
++ 'gdbus-auth-mechanism-sha1': {'extra_sources' : extra_sources},
+ 'gdbus-bz627724' : {'extra_sources' : extra_sources},
+ 'gdbus-close-pending' : {'extra_sources' : extra_sources},
+ 'gdbus-connection' : {
+--
+2.35.6
diff --git a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
index e15aa1fe206..70b0b74e881 100644
--- a/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
+++ b/meta/recipes-core/glib-2.0/glib-2.0_2.78.6.bb
@@ -54,6 +54,10 @@ SRC_URI = "${GNOME_MIRROR}/glib/${SHRT_VER}/glib-${PV}.tar.xz \
file://CVE-2026-58012.patch \
file://CVE-2026-58013.patch \
file://CVE-2026-58014.patch \
+ file://CVE-2026-58015_p1.patch \
+ file://CVE-2026-58015_p2.patch \
+ file://CVE-2026-58015_p3.patch \
+ file://CVE-2026-58015_p4.patch \
"
SRC_URI:append:class-native = " file://relocate-modules.patch \
file://0001-meson.build-do-not-enable-pidfd-features-on-native-g.patch \
diff --git a/meta/recipes-core/glib-2.0/glib.inc b/meta/recipes-core/glib-2.0/glib.inc
index fac8875d844..5b69c9d7d3e 100644
--- a/meta/recipes-core/glib-2.0/glib.inc
+++ b/meta/recipes-core/glib-2.0/glib.inc
@@ -39,7 +39,7 @@ PACKAGECONFIG ??= "libmount \
PACKAGECONFIG[libmount] = "-Dlibmount=enabled,-Dlibmount=disabled,util-linux"
PACKAGECONFIG[manpages] = "-Dman=true, -Dman=false, libxslt-native xmlto-native"
PACKAGECONFIG[libelf] = "-Dlibelf=enabled,-Dlibelf=disabled,elfutils"
-PACKAGECONFIG[tests] = "-Dinstalled_tests=true,-Dinstalled_tests=false,"
+PACKAGECONFIG[tests] = "-Dinstalled_tests=true,-Dinstalled_tests=false,dbus-native"
PACKAGECONFIG[selinux] = "-Dselinux=enabled,-Dselinux=disabled,libselinux"
EXTRA_OEMESON = "-Ddtrace=false -Dsystemtap=false"
^ permalink raw reply related [flat|nested] 25+ messages in thread* [OE-core][scarthgap 08/11] curl: fix CVE-2025-10148 backport for websockets on 8.7.1
2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
` (6 preceding siblings ...)
2026-08-25 10:06 ` [OE-core][scarthgap 07/11] glib-2.0: fix CVE-2026-58015 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 09/11] bitbake.conf: add TMPDIR to GIT_CEILING_DIRECTORIES Yoann Congal
` (2 subsequent siblings)
10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
To: openembedded-core
From: Etienne Cordonnier <ecordonnier@snap.com>
The original backport applied upstream's CURLcode return path into
ssize_t ws_enc_write_head(), which uses an undeclared result and is
invalid for curl 8.7.1's API. Builds with --enable-websockets fail.
Adapt Curl_rand() error handling to set *err and return -1.
AI-Generated: Claude Sonnet 4.6
Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
.../curl/curl/CVE-2025-10148.patch | 24 +++++++++++--------
1 file changed, 14 insertions(+), 10 deletions(-)
diff --git a/meta/recipes-support/curl/curl/CVE-2025-10148.patch b/meta/recipes-support/curl/curl/CVE-2025-10148.patch
index d37497febe9..654f4151e99 100644
--- a/meta/recipes-support/curl/curl/CVE-2025-10148.patch
+++ b/meta/recipes-support/curl/curl/CVE-2025-10148.patch
@@ -9,23 +9,28 @@ Closes #18496
CVE: CVE-2025-10148
Upstream-Status: Backport [https://github.com/curl/curl/commit/84db7a9eae8468c0445b15aa806fa]
Signed-off-by: Hitendra Prajapati <hprajapati@mvista.com>
+Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com>
---
- lib/ws.c | 21 +++++++++++++--------
- 1 file changed, 13 insertions(+), 8 deletions(-)
+ lib/ws.c | 25 +++++++++++++++++--------
+ 1 file changed, 17 insertions(+), 8 deletions(-)
diff --git a/lib/ws.c b/lib/ws.c
index 5bc5ecc..02e0ef0 100644
--- a/lib/ws.c
+++ b/lib/ws.c
-@@ -614,6 +614,18 @@ static ssize_t ws_enc_write_head(struct Curl_easy *data,
+@@ -614,6 +614,22 @@ static ssize_t ws_enc_write_head(struct Curl_easy *data,
enc->payload_remain = enc->payload_len = payload_len;
ws_enc_info(enc, data, "sending");
-+ /* 4 bytes random */
-+
-+ result = Curl_rand(data, (unsigned char *)&enc->mask, sizeof(enc->mask));
-+ if(result)
-+ return result;
++ /* 4 bytes random */
++ {
++ CURLcode result = Curl_rand(data, (unsigned char *)&enc->mask,
++ sizeof(enc->mask));
++ if(result) {
++ *err = result;
++ return -1;
++ }
++ }
+
+#ifdef DEBUGBUILD
+ if(getenv("CURL_WS_FORCE_ZERO_MASK"))
@@ -36,7 +41,7 @@ index 5bc5ecc..02e0ef0 100644
/* add 4 bytes mask */
memcpy(&head[hlen], &enc->mask, 4);
hlen += 4;
-@@ -802,14 +814,7 @@ CURLcode Curl_ws_accept(struct Curl_easy *data,
+@@ -802,14 +818,7 @@ CURLcode Curl_ws_accept(struct Curl_easy *data,
subprotocol not requested by the client), the client MUST Fail
the WebSocket Connection. */
@@ -54,4 +59,3 @@ index 5bc5ecc..02e0ef0 100644
result = Curl_cwriter_create(&ws_dec_writer, data, &ws_cw_decode,
--
2.50.1
-
^ permalink raw reply related [flat|nested] 25+ messages in thread* [OE-core][scarthgap 09/11] bitbake.conf: add TMPDIR to GIT_CEILING_DIRECTORIES
2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
` (7 preceding siblings ...)
2026-08-25 10:06 ` [OE-core][scarthgap 08/11] curl: fix CVE-2025-10148 backport for websockets on 8.7.1 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 10/11] bison: patch CVE-2026-56389 Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 11/11] rpcbind: Fix CVE-2026-16277 Yoann Congal
10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
To: openembedded-core
From: Ross Burton <ross.burton@arm.com>
We export GIT_CEILING_DIRECTORIES=WORKDIR to ensure that git calls
inside the builds don't find oe-core when they're meant to be looking
for the git repository of the source code.
However, this breaks for recipes that use work-shared (such as llvm), as
their working directory is outside of WORKDIR.
Solve this by adding TMPDIR to the list as a final catch, but keeping
WORKDIR first so that git will stop sooner in the general case.
This solves reproduciblity problems in LLVM, where for example lld's
version string would contain the URL and commit hash of the poky repo
being built.
Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(cherry picked from commit f42f0185bd00e68ecc86a930487f21fc86214cfa)
Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com>
[fatho: edit commit message by adding "cherry picked from"]
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
meta/conf/bitbake.conf | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/meta/conf/bitbake.conf b/meta/conf/bitbake.conf
index e20b17fad6f..3fd442edbdd 100644
--- a/meta/conf/bitbake.conf
+++ b/meta/conf/bitbake.conf
@@ -786,9 +786,9 @@ export PKG_CONFIG_DISABLE_UNINSTALLED = "yes"
export PKG_CONFIG_SYSTEM_LIBRARY_PATH = "${base_libdir}:${libdir}"
export PKG_CONFIG_SYSTEM_INCLUDE_PATH = "${includedir}"
-# Don't allow git to chdir up past WORKDIR so that it doesn't detect the OE
-# repository when building a recipe
-export GIT_CEILING_DIRECTORIES = "${WORKDIR}"
+# Don't allow git to chdir up past WORKDIR or TMPDIR so that it doesn't detect the OE
+# repository when building a recipe.
+export GIT_CEILING_DIRECTORIES = "${WORKDIR}:${TMPDIR}"
###
### Config file processing
^ permalink raw reply related [flat|nested] 25+ messages in thread* [OE-core][scarthgap 10/11] bison: patch CVE-2026-56389
2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
` (8 preceding siblings ...)
2026-08-25 10:06 ` [OE-core][scarthgap 09/11] bitbake.conf: add TMPDIR to GIT_CEILING_DIRECTORIES Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
2026-08-25 10:06 ` [OE-core][scarthgap 11/11] rpcbind: Fix CVE-2026-16277 Yoann Congal
10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
To: openembedded-core
From: Peter Marko <peter.marko@siemens.com>
Pick patch mentioned in NVD CVE report.
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
(From OE-Core rev: 6c99410bd7f0bc4e2ed41ef5afe7d6b5fcb99837)
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
.../bison/bison/CVE-2026-56389.patch | 56 +++++++++++++++++++
meta/recipes-devtools/bison/bison_3.8.2.bb | 1 +
2 files changed, 57 insertions(+)
create mode 100644 meta/recipes-devtools/bison/bison/CVE-2026-56389.patch
diff --git a/meta/recipes-devtools/bison/bison/CVE-2026-56389.patch b/meta/recipes-devtools/bison/bison/CVE-2026-56389.patch
new file mode 100644
index 00000000000..ac827f6314a
--- /dev/null
+++ b/meta/recipes-devtools/bison/bison/CVE-2026-56389.patch
@@ -0,0 +1,56 @@
+From 3169c1e7a2c6acc4c59dfcf8b089896d6881925b Mon Sep 17 00:00:00 2001
+From: Paul Eggert <eggert@cs.ucla.edu>
+Date: Thu, 23 Apr 2026 09:20:43 -0700
+Subject: [PATCH] html: use xsltproc from PATH
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+* src/print-xml.c (print_html):
+* src/reader.c (prepare_percent_define_front_end_variables):
+Drop undocumented support for lines like ‘%define tool.xsltproc
+"whatever"’, as this can cause more trouble than it cures.
+
+CVE: CVE-2026-56389
+Upstream-Status: Backport [https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=3169c1e7a2c6acc4c59dfcf8b089896d6881925b]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/print-xml.c | 4 +---
+ src/reader.c | 1 -
+ 2 files changed, 1 insertion(+), 4 deletions(-)
+
+diff --git a/src/print-xml.c b/src/print-xml.c
+index 8da6da0d..79bfa88d 100644
+--- a/src/print-xml.c
++++ b/src/print-xml.c
+@@ -543,10 +543,9 @@ print_html (void)
+ assert (xml_flag);
+
+ char *xml2html = xpath_join (pkgdatadir (), "xslt/xml2xhtml.xsl");
+- char *xsltproc = muscle_percent_define_get ("tool.xsltproc");
+ char const *argv[11];
+ int i = 0;
+- argv[i++] = xsltproc;
++ argv[i++] = "xsltproc";
+ argv[i++] = "-o";
+ argv[i++] = spec_html_file;
+ argv[i++] = xml2html;
+@@ -572,6 +571,5 @@ print_html (void)
+ /* termsigp */ NULL);
+ if (status)
+ complain (NULL, complaint, _("%s failed with status %d"), argv[0], status);
+- free (xsltproc);
+ free (xml2html);
+ }
+diff --git a/src/reader.c b/src/reader.c
+index 862d7293..cb2a7f69 100644
+--- a/src/reader.c
++++ b/src/reader.c
+@@ -788,7 +788,6 @@ prepare_percent_define_front_end_variables (void)
+ muscle_percent_define_default ("lr.default-reduction", "accepting");
+ free (lr_type);
+ }
+- muscle_percent_define_default ("tool.xsltproc", "xsltproc");
+
+ /* Check %define front-end variables. */
+ {
diff --git a/meta/recipes-devtools/bison/bison_3.8.2.bb b/meta/recipes-devtools/bison/bison_3.8.2.bb
index da138e35874..9808a96e993 100644
--- a/meta/recipes-devtools/bison/bison_3.8.2.bb
+++ b/meta/recipes-devtools/bison/bison_3.8.2.bb
@@ -12,6 +12,7 @@ DEPENDS = "bison-native flex-native"
SRC_URI = "${GNU_MIRROR}/bison/bison-${PV}.tar.xz \
file://autoconf-2.73.patch \
file://add-with-bisonlocaledir.patch \
+ file://CVE-2026-56389.patch \
"
SRC_URI[sha256sum] = "9bba0214ccf7f1079c5d59210045227bcf619519840ebfa80cd3849cff5a5bf2"
^ permalink raw reply related [flat|nested] 25+ messages in thread* [OE-core][scarthgap 11/11] rpcbind: Fix CVE-2026-16277
2026-08-25 10:06 [OE-core][scarthgap 00/11] Patch review Yoann Congal
` (9 preceding siblings ...)
2026-08-25 10:06 ` [OE-core][scarthgap 10/11] bison: patch CVE-2026-56389 Yoann Congal
@ 2026-08-25 10:06 ` Yoann Congal
10 siblings, 0 replies; 25+ messages in thread
From: Yoann Congal @ 2026-08-25 10:06 UTC (permalink / raw)
To: openembedded-core
From: Vijay Anusuri <vanusuri@mvista.com>
Pick patch according to [2]
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-16277
[2] https://security-tracker.debian.org/tracker/CVE-2026-16277
Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr>
---
.../rpcbind/rpcbind/CVE-2026-16277.patch | 34 +++++++++++++++++++
.../recipes-extended/rpcbind/rpcbind_1.2.6.bb | 1 +
2 files changed, 35 insertions(+)
create mode 100644 meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch
diff --git a/meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch b/meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch
new file mode 100644
index 00000000000..868e5c3f01c
--- /dev/null
+++ b/meta/recipes-extended/rpcbind/rpcbind/CVE-2026-16277.patch
@@ -0,0 +1,34 @@
+From bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d Mon Sep 17 00:00:00 2001
+From: Steve Dickson <steved@redhat.com>
+Date: Wed, 27 May 2026 11:42:11 -0400
+Subject: [PATCH] rpcinfo: stack buffer overflow in rpcinfo rpcbaddrlist()
+
+rpcinfo's rpcbaddrlist() formats two server-controlled, unbounded XDR strings into a fixed 128-byte stack buffer with sprintf(). A malicious or on-path rpcbind server overflows it when a user runs:
+rpcinfo -l <host> <prognum> <versnum>
+
+Reported-by: Michalis Vasileiadis <vmihalis.tmd@gmail.com>
+Signed-off-by: Steve Dickson <steved@redhat.com>
+
+Upstream-Status: Backport [https://git.linux-nfs.org/?p=steved/rpcbind.git;a=commitdiff;h=bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d]
+CVE: CVE-2026-16277
+Signed-off-by: Vijay Anusuri <vanusuri@mvista.com>
+---
+ src/rpcinfo.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/src/rpcinfo.c b/src/rpcinfo.c
+index 0e14f78..43e8115 100644
+--- a/src/rpcinfo.c
++++ b/src/rpcinfo.c
+@@ -1120,7 +1120,7 @@ rpcbaddrlist (netid, argc, argv)
+
+ re = &head->rpcb_entry_map;
+ printf ("%10u%3u ", parms.r_prog, parms.r_vers);
+- sprintf (buf, "%s/%s/%s ",
++ snprintf (buf, sizeof(buf), "%s/%s/%s ",
+ re->r_nc_protofmly, re->r_nc_proto,
+ re->r_nc_semantics == NC_TPI_CLTS ? "clts" :
+ re->r_nc_semantics == NC_TPI_COTS ? "cots" : "cots_ord");
+--
+2.43.0
+
diff --git a/meta/recipes-extended/rpcbind/rpcbind_1.2.6.bb b/meta/recipes-extended/rpcbind/rpcbind_1.2.6.bb
index dbd4d32e0a0..07e2f10c98a 100644
--- a/meta/recipes-extended/rpcbind/rpcbind_1.2.6.bb
+++ b/meta/recipes-extended/rpcbind/rpcbind_1.2.6.bb
@@ -15,6 +15,7 @@ SRC_URI = "${SOURCEFORGE_MIRROR}/rpcbind/rpcbind-${PV}.tar.bz2 \
file://rpcbind.conf \
file://rpcbind_add_option_to_fix_port_number.patch \
file://0001-systemd-use-EnvironmentFile.patch \
+ file://CVE-2026-16277.patch \
"
SRC_URI[sha256sum] = "5613746489cae5ae23a443bb85c05a11741a5f12c8f55d2bb5e83b9defeee8de"
^ permalink raw reply related [flat|nested] 25+ messages in thread